Privacy
Policy
1. Who We Are
Mushaf · القرآن الكريم ("Mushaf", "the app", "we", "us") is a Quran reader and companion app for iOS, built and maintained by Rami Al-Karo in Helsinki, Finland.
This policy explains what information Mushaf collects, why, and what control you have. We aim to collect as little as possible — most of what you do in the app stays on your device.
Short version: Mushaf does not sell your data, does not run ads, and does not use third-party analytics or tracking SDKs. Sign-in is optional. Your bookmarks, favorites, and reading position stay on your device unless you choose to sign in to sync them.
2. What We Collect
2.1 On-Device Only (never sent anywhere)
The following is stored in your phone's local storage (SharedPreferences) and never leaves the device unless you explicitly sign in to sync:
- Bookmarked ayahs and saved verses
- Favorite surahs and favorite qari
- Last-read mushaf page
- Display preferences: theme (light/dark), text size, language
- Most recent playback state (which qari, whether playing)
- Cached GPS coordinates (used only for prayer-time calculation — see §2.4)
2.2 If You Sign In (Optional)
Sign-in is not required to use the app. If you choose to sign in with Apple or Google, we receive and store in our Firestore database:
- Your Firebase-issued account ID (uid)
- Your email address (if you share it during sign-in)
- Your display name and profile image URL (if provided by Apple/Google)
- Your device timezone (used for scheduling reminders correctly)
- The platform you signed up from (iOS or Android)
We do not receive your password. Apple and Google handle authentication.
2.3 Subscription / In-App Purchase
Mushaf has no active paid products at this time — the app is free to use. The app is built on top of RevenueCat's SDK so that future premium features (if any) can be managed correctly. As a result, the RevenueCat SDK initializes at app launch and, when you sign in, receives your Firebase user ID to prepare for any future purchase. No payment information is collected unless and until a paid product is launched and you choose to buy it.
2.4 Location (Prayer Times)
If you enable prayer times, the app asks for location access to
compute accurate prayer times for your area. Your GPS coordinates
are cached on your device and are used only by the
on-device prayer-time calculator. We do not transmit
your coordinates to our servers. If you sign in, only your timezone
(e.g. Europe/Helsinki) is stored in your profile for
scheduling purposes — not your coordinates.
2.5 Usage Analytics / Crash Reports
Mushaf does not include any third-party analytics SDK, advertising SDK, or crash reporting SDK. We do not track screen views, feature usage, or device identifiers beyond what is required to render content (for example, the Firebase-issued user ID if you sign in).
3. How We Use It
We use the limited information we do collect only to:
- Authenticate you when you sign in (Firebase Auth)
- Sync your saved ayahs, favorites, and reading position across your devices (only if signed in)
- Schedule prayer-time notifications correctly for your timezone
- Serve qari audio and adhkar content via our content backend (Firestore)
- Respond to your support requests if you contact us
We do not use your data for advertising, profiling, or sale to third parties.
4. Data Sharing
We share data with a small number of service providers who process it on our behalf:
| Service | What's shared | Why |
|---|---|---|
| Google Firebase (Authentication + Firestore) | Account ID, email, display name, profile image URL, timezone, platform — only if you sign in | Sign-in and profile sync. Hosted by Google Cloud. |
| Apple Sign In / Google Sign In | Sign-in request | Authenticating your identity when you choose to sign in |
| RevenueCat | Firebase user ID on login (only if you sign in). No payment information at this time. | SDK wired for future subscription management. No paid products are active. |
| quran.com API | Anonymous HTTP requests for Quran page content — no user identifier is sent | Fetching the Quran text you read |
| Audio content delivery networks | Anonymous HTTP request for qari recitation MP3s | Streaming the audio when you listen to a qari |
We do not sell personal data to anyone. We do not share personal data with advertisers. We do not use marketing SDKs.
5. Device Permissions
Mushaf requests the following device permissions. You can revoke any of them at any time in your device settings.
iOS
- Location (When In Use / Always) — to compute prayer times for your area. Used on-device only.
- Background Audio — to continue qari recitation playback when the app is backgrounded or your screen is locked.
Android
- Location (Fine / Coarse / Background) — to compute prayer times. Used on-device only.
- Post Notifications — to show playback controls and (optionally) prayer-time reminders.
- Schedule Exact Alarm — for accurate reminder scheduling.
- Foreground Service — to keep audio playing when the app is backgrounded.
- Wake Lock — to keep audio from being paused by the system during playback.
- Receive Boot Completed — to re-register reminder schedules after a reboot.
- Internet — required for signing in and streaming audio.
Mushaf does not request access to your camera, microphone, contacts, photos, or phone identifiers.
6. Data Retention
On-device data (bookmarks, favorites, preferences) is retained on your device until you uninstall Mushaf or manually clear it.
Account data (uid, email, display name, timezone, platform) is retained in Firestore as long as your account exists. If you delete your account, we delete this profile data within 30 days. See §9 for how to request deletion.
We do not keep access logs of what you read, listen to, or bookmark.
7. Security
All network requests are made over HTTPS (TLS). Firebase Authentication, Firestore, and RevenueCat are industry-standard services hosted by Google and RevenueCat respectively.
No system is perfectly secure. If we become aware of a breach that affects your data, we will notify you as required by applicable law (for example, within 72 hours under GDPR).
8. Children's Privacy
Mushaf is not directed at children under 13 and we do not knowingly collect personal information from children under 13. If you believe a child under 13 has provided us with personal information, please contact us at the address in §13 and we will delete it.
9. Your Rights
You have the right to:
- Access the personal data we have about you
- Correct any inaccurate information
- Delete your account and associated data
- Export your data in a portable format
- Revoke consent (for example, by signing out or uninstalling the app)
- Object to specific kinds of processing
- Lodge a complaint with a supervisory authority
To exercise any of these rights, email the address in §13. We will respond within 30 days.
10. European Users (GDPR)
If you are in the European Economic Area, the United Kingdom, or Switzerland, the General Data Protection Regulation (GDPR) applies to our processing of your personal data.
Legal bases we rely on:
- Consent — for location use and, if applicable, push notifications
- Contract — to provide the sign-in, sync, and audio playback features you request
- Legitimate interest — to keep the service running, prevent abuse, and respond to support requests
Data controller: Rami Al-Karo, Helsinki, Finland. Data transfers: Firebase and RevenueCat may process data in the United States. Both rely on Standard Contractual Clauses for EU-to-US transfers.
11. California Residents (CCPA/CPRA)
If you are a California resident, the California Consumer Privacy Act gives you specific rights over your personal information.
We do not sell or share personal information for cross-context behavioral advertising.
You may request:
- Knowledge of what personal information we collect, use, and disclose
- Deletion of your personal information
- Correction of inaccurate personal information
- Opt-out of sale or share (we do not sell or share)
- Limits on use of sensitive personal information (we do not use sensitive PI for purposes requiring opt-out)
To exercise any of these, contact us at the address in §13.
12. Policy Changes
We may update this policy to reflect changes to the app or applicable law. When we do, we'll update the "Last Updated" date at the top of this page. If the change is material, we'll surface a notice in the app or by email (if you've signed in).
Your continued use of Mushaf after an update means you accept the revised policy.
13. Contact Us
Questions, requests, or concerns about this policy or your data? Reach us at:
- Email: rami.alkaro@gmail.com
- Support page: mushaf.ramialkaro.fi/support